Staff Security Engineer
Melbourne, Victoria, Australia · Contract
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
The Infrastructure team supports the foundational platform for global marketplaces, focusing on system reliability, scalability, and performance primarily on AWS ECS and EKS (Kubernetes). As a Staff Security Engineer, you will lead security initiatives across DEAP properties, making risks visible, addressing gaps, and ensuring security best practices are implemented and maintained. This senior individual contributor role combines hands-on work, standard establishment, process management, coaching, and close collaboration with Infrastructure and DevOps teams. The role involves evolving responsibilities aligned with our maturing security strategy.
Key Responsibilities
- Maintain an up-to-date inventory of applications, services, and data flows across multiple marketplaces.
- Implement and optimize security assurance processes integrated into CI/CD pipelines, including SAST, DAST, dependency/SCA, container, and infrastructure scanning.
- Manage triage and remediation of findings from automated tools and external penetration tests within defined SLAs.
- Develop security champions within delivery teams to scale security practices.
- Lead PCI DSS compliance activities such as scope definition, SAQ/ROC completion, ASV scans, segmentation evidence, and audit coordination.
- Manage continuous evidence collection for audits and maintain a comprehensive risk register with clear ownership and reporting to leadership.
- Collaborate with legal and privacy teams on technical controls relating to data retention, deletion, and access compliance (GDPR/CCPA).
- Oversee access governance processes including joiner/mover/leaver handling and quarterly recertification ensuring least-privilege IAM.
- Own and refine the security incident response process, serve as incident commander, and ensure thorough post-incident reviews with tracked outcomes.
- Coordinate bot management to monitor load and cost impacts, tuning mitigation strategies proactively.
- Enhance logging quality to minimize error logs and ensure proper triaging over time.
- Assess security and operational risks of new technical vendors before onboarding and participate in renewal and contract management for vendor spend optimization.
- Maintain and prioritize a backlog of security improvements aligned with engineering and product planning cycles.
About the Employer
Articore operates major creator marketplaces including Redbubble, TeePublic, Dashery, and Frankly Wearing, with vast catalogs like Redbubble’s 40 billion SKUs.
Candidate Profile
- Extensive experience in security engineering, DevSecOps, platform security or security operations for production SaaS or marketplaces.
- Proficient in running/tuning SAST, DAST, SCA, container, and infrastructure scanning integrated into CI/CD pipelines and managing penetration testing findings.
- Experienced as incident commander in security incident response including conducting blameless postmortems with actionable follow-up.
- Familiarity with PCI DSS or similar control frameworks, risk registers, access recertification, and communicating risk to leadership in non-technical terms.
- Comfortable working in cloud-native environments, preferably AWS.
- Demonstrated ability to influence outcomes as a senior individual contributor by proposing initiatives, gaining consensus, and coaching engineers without direct authority.
- Experience in vendor security review processes, IT financial stewardship including SOC reports, DPAs, and contract management.
- Practical experience with large-scale bot management and traffic mitigation tools such as Cloudflare.
- Utilizes AI tools in work processes with interest in further integration.
- Adaptable to evolving role requirements and the development of security strategy beyond checklist execution.
- Proven track record working effectively in a global organization with asynchronous communication and decision-making across time zones.
- Ability to simplify technical complexities for diverse stakeholders and align decision-makers on project timelines, scope, and risks.
- Skilled at balancing system health priorities with delivery demands and managing multiple ambiguous priorities.
- Inclusive collaborator engaging diverse stakeholders and confidently leading through organizational changes.
Work Environment
- Hybrid work setting requiring presence onsite one to two days per week in Melbourne.
- Collaborative effort with global teams across different time zones.
Benefits and Culture
- High-trust organizational environment promoting mutual respect and employee voice.
- Flexible scheduling to support work-life balance.
- Global career opportunities offering diverse experiences.
- Monthly wellness allowance dedicated to personal health and well-being.
- Access to exclusive vouchers and discounts on online marketplaces.
Level
Mid
Industry
Mining